Set up Single Sign-On (SSO) for G Suite accounts using third party identity providers

The SAML-based Federated SSO article describes the SAML instance where Google is the identity provider (IdP). This group of articles describes the SAML instance where Google is the service provider (SP) and uses 3rd party identity providers.

To set up Google service provider SAML with 3rd party IdPs, step through the process by following the blue links or the arrows above:

SSO for G Suite support

SSO enables users to access all of their enterprise cloud applications—including administrators signing in to the Admin console—by signing in one time for all services. If a user tries to sign in to the Admin console or another Google service when SSO is set up, they are redirected to the SSO sign-in page.

We provide a Security Assertion Markup Language (SAML)-based SSO API that you can use to integrate into your Lightweight Directory Access Protocol (LDAP), or other SSO system. LDAP is a networking protocol for querying and modifying directory services running over TCP/IP.

Pre-2.1 Android devices use Google authentication. If you try to sign in with these devices, you are prompted for your full G Suite account email address (including username and domain) and you go directly to the application after you sign in. Google does not redirect you to the SSO sign-in page, regardless of the network mask.

With iOS applications, when the SSO Sign-in page URL starts with "google." (or some variation), the Google iOS app is redirected to Safari. This causes the SSO process to fail. The full list of forbidden prefixes is:

googl.

google.

www.googl.

www.google.

You'll need to change any SSO Sign-in page URLs with these prefixes.

How does the password change URL affect password changes?

If you specify a URL in the Change password URL option, all users, other than super administrators, who try to change their password at https://myaccount.google.com/ will be directed to the URL you specify. This setting applies even if you do not enable SSO. Also, network masks do not apply.

I have a question that is not covered above.

To resolve common issues, see Troubleshooting Single Sign-On. There are also a number of commercial products and system integrators that provide SSO products and professional services. Search the G Suite Marketplace for Google Cloud partners and other third parties that provide SSO assistance.